Skip to content

Commit b779ceb

Browse files
committed
final fixes
1 parent 7ab4b2a commit b779ceb

File tree

2 files changed

+20
-21
lines changed

2 files changed

+20
-21
lines changed

articles/defender-for-cloud/data-aware-security-dashboard-overview.md

Lines changed: 18 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.topic: conceptual
77
ms.date: 02/11/2024
88
---
99

10-
# Data security dashboard
10+
# Data security dashboard (Preview)
1111

1212
Microsoft Defender for Cloud's data security dashboard provides an interactive view of significant risks to sensitive data. It prioritizes alerts and potential attack paths across multicloud data resources, making data protection management more effective.
1313

@@ -19,14 +19,6 @@ With the data security dashboard you can:
1919
- Explore potential threats data by highlighting [attack paths](concept-attack-path.md) that lead to sensitive data.
2020
- Explore useful data insights by highlighting useful data queries in the [security explorer](how-to-manage-cloud-security-explorer.md).
2121

22-
You can select any element on the page to get more detailed information.
23-
24-
| Aspect | Details |
25-
|---------|---------|
26-
|Release state: | Public Preview |
27-
| Required roles and permissions: | Security explorer. |
28-
| Clouds: | :::image type="icon" source="./media/icons/yes-icon.png"::: Commercial clouds <br/> :::image type="icon" source="./media/icons/no-icon.png"::: Azure Government <br/> :::image type="icon" source="./media/icons/no-icon.png"::: Azure China 21Vianet |
29-
3022
## Prerequisites
3123

3224
**To view the dashboard**:
@@ -37,42 +29,47 @@ You can select any element on the page to get more detailed information.
3729
**To receive the alerts for data sensitivity**:
3830
- You must [enable Defender for Storage](tutorial-enable-storage-plan.md).
3931

40-
> [!NOTE]
41-
> The data security dashboard feature is turned on at the subscription level.
42-
4332
## Required permissions and roles
4433

4534
To view the dashboard you must have either of the following:
4635

4736
**Permissions**:
4837

49-
- Microsoft.Security/assessments/read
50-
- Microsoft.Security/assessments/subassessments/read
51-
- Microsoft.Security/alerts/read
38+
- Microsoft.Security/assessments/read
39+
- Microsoft.Security/assessments/subassessments/read
40+
- Microsoft.Security/alerts/read
41+
42+
**Role** - the minimum required privileged RBAC role of **Security explorerr**.
5243

53-
- **Role** - the minimum required privileged RBAC role of **Security Reader**.
44+
- Register each relevant Azure subscription to the [Microsoft.Security resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
5445

55-
Register each relevant Azure subscription to the [Microsoft.Security resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
46+
> [!NOTE]
47+
> The data security dashboard feature is turned on at the subscription level.
5648
5749
## Data security overview section
5850

5951
The data security overview section provides a general overview of your cloud data estate, per cloud, including all data resources, divided into storage assets, managed databases, and hosted databases (IaaS).
6052

6153
:::image type="content" source="media/data-aware-security-dashboard/data-security-overview.png" alt-text="Screenshot that shows the overview section of the data security view." lightbox="media/data-aware-security-dashboard/data-security-overview.png":::
6254

63-
**By coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
55+
- **Coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
56+
57+
- **Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
58+
- **Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
59+
-** Not covered** - resources that are not covered by Defender CSPM, or Defender for Storage, or Defender for Databases.
6460

65-
- **Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
66-
- **Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
6761
- **Sensitive resources** – displays how many resources are sensitive.
68-
- **Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
62+
63+
- **Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
6964

7065
## Top issues
7166

7267
The **Top issues** section provides a highlighted view of top active and potential risks to sensitive data.
7368

7469
- **Sensitive data resources with high severity alerts** - summarizes the active threats to sensitive data resources and which data types are at risk.
70+
7571
- **Sensitive data resources in attack paths** - summarizes the potential threats to sensitive data resources by presenting attack paths leading to sensitive data resources and which data types are at potential risk.
72+
7673
- **Data queries in security explorer** - presents the top data-related queries in security explorer that helps focus on multicloud risks to sensitive data.
7774

7875
:::image type="content" source="media/data-aware-security-dashboard/top-issues.png" alt-text="Screenshot that shows the top issues section of the data security view." lightbox="media/data-aware-security-dashboard/top-issues.png":::

articles/defender-for-cloud/support-matrix-cloud-environment.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,8 @@ In the support table, **NA** indicates that the feature isn't available.
3131
|[Recommendation exemptions](exempt-resource.md) | Preview | NA | NA|
3232
|[Secure score](secure-score-security-controls.md) | GA | GA | GA|
3333
|[DevOps security posture](concept-devops-environment-posture-management-overview.md) | Preview | NA | NA|
34+
| **DEFENDER CSPM FEATURES** | | | |
35+
| [Data security dashboard](data-aware-security-dashboard-overview.md) | Preview | NA | NA |
3436
|**DEFENDER FOR CLOUD PLANS** | | ||
3537
|[Defender CSPM](concept-cloud-security-posture-management.md)| GA | NA | NA|
3638
|[Defender for APIs](defender-for-apis-introduction.md). | GA | NA | NA|

0 commit comments

Comments
 (0)